Intel

AIKIDO-2026-10684

astral-tokio-tar is vulnerable to UNIX Symbolic Link (Symlink) Following

UNIX Symbolic Link (Symlink) FollowingGHSA-xx64-wwv2-hcqq Published Apr 30, 2026

30

Low Risk

This Affects:

RUSTastral-tokio-tar
0.0.1 - 0.6.0
Fixed in 0.6.1
Are you affected? Scan for Free

TL;DR

In affected versions of this package, the unpack_in API could inadvertently modify the permissions of external (i.e. non-archive) directories outside of the archive. An attacker could use this to contrite a tar archive that maliciously changes directory permissions outside of its intended hierarchy. This flaw only affects directories; individual file permissions cannot be modified via it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

astral-tokio-tar is vulnerable to UNIX Symbolic Link (Symlink) Following in versions 0.0.1 - 0.6.0.

How to fix this

Upgrade the astral-tokio-tar library to the patch version.